Articles Tagged “Vulnerability Management”
9 articles found
OWASP Subtractive Security Scores What You Remove
OWASP launched a Subtractive Security Top 10 with nine platform lists and a Path Erasure Rate metric that counts attack paths deleted, not alerts raised.
Next.js Ships First Pre-Announced Security Update
Next.js patched 9 CVEs in v16.2.11 and v15.5.21 — its first pre-announced monthly security release, giving teams time to plan upgrades before disclosure.
7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.
Microsoft Secure Future Initiative Hits New Milestones
Microsoft's July 2026 Secure Future Initiative report: phishing-resistant MFA on 99.97% of accounts, 732K+ resources locked down, and AI-driven defense.
CVE Lite CLI Scans npm Projects Right in Your Terminal
CVE Lite CLI, now an OWASP Incubator project, checks JavaScript lockfiles against the OSV database and suggests one-line fixes for npm, pnpm, Yarn, and Bun.
Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.
CISA's BOD 26-04 Shifts Federal Patching to a Smarter Risk-Based Model
CISA's new Binding Operational Directive 26-04 tells agencies to patch smarter, prioritizing vulnerabilities that are internet-facing, automatable, high-impact, and actively exploited.
Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.
AI Browser Extensions Are Your Enterprise's Biggest Unmanaged Security Surface
LayerX's 2026 Browser Extension Security Report reveals AI extensions carry 60% more CVEs and access cookies 3x more than standard extensions — with 15% of enterprise users already exposed.









